#!/bin/bash

# 创建证书目录
mkdir -p cert

# 生成私钥
openssl genrsa -out cert/key.pem 2048

# 生成证书签名请求
openssl req -new -key cert/key.pem -out cert/csr.pem \
    -subj "/C=CN/ST=State/L=City/O=Organization/OU=Department/CN=localhost"

# 生成自签名证书
openssl x509 -req -days 365 -in cert/csr.pem -signkey cert/key.pem -out cert/cert.pem

# 清理临时文件
rm cert/csr.pem

echo "自签名证书已生成在 cert 目录下"
